doc-prd-fixer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (e.g., mkdir -p .aidoc/review/02_PRD/<PRD-id>/) using variables derived from the artifact metadata. If the artifact ID in the audit report is maliciously crafted with shell metacharacters (e.g., PRD-01; rm -rf /), it could lead to arbitrary command execution on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a "remediation stage" that ingests untrusted data from audit reports (.aidoc/audit/02_PRD-audit.md) and persona validation slots to modify project documentation and generate new content.
  • Ingestion points: Reads .aidoc/audit/02_PRD-audit.md, verdict.json, and persona-specific JSON slots.
  • Boundary markers: No explicit boundary markers or "ignore previous instructions" warnings are used when processing the audit findings into the PRD content during Phase 4 (Content) or Phase 7 (Style).
  • Capability inventory: The skill has high privileges including writing to the filesystem, creating/modifying directories, and dispatching other subagents.
  • Sanitization: There is no evidence of sanitization or character escaping for the content being applied from the audit report to the target PRD.
  • [TIME_DELAYED_CONDITIONAL]: The skill implements a break-circuit policy using SOFT_DEADLINE (1500s) checks and wall-clock time comparisons to trigger partial timeouts and transition saga states. This is implemented for functional safety but relies on external state files (.skill-start.fixer) that could be manipulated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:18 PM
Security Audit — agent-trust-hub — doc-prd-fixer